]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
iommufd: Reject DMABUF pages from the access pin path
authorPeiyang He <peiyang_he@smail.nju.edu.cn>
Thu, 9 Jul 2026 05:08:00 +0000 (13:08 +0800)
committerJason Gunthorpe <jgg@nvidia.com>
Mon, 13 Jul 2026 17:27:44 +0000 (14:27 -0300)
DMABUF pages are not supported for iommufd access pinning.
iommufd_access_pin_pages() returns struct page pointers for
in-kernel CPU access, but DMABUF-backed iopt_pages do not carry
a userspace address that can be passed to the GUP path.

iopt_pages_rw_access() already rejects IOPT_ADDRESS_DMABUF before doing
CPU access. Apply the same rejection to iopt_area_add_access() before it
takes pages->mutex and calls iopt_pages_fill_xarray().
Otherwise a DMABUF-backed iopt_pages can reach the hole-fill path, where
pfn_reader_user_pin() interprets the union as uptr and
calls pin_user_pages_fast()/pin_user_pages_remote().

This fix also avoids the lockdep warning reported from that path, where
pages_dmabuf_mutex_key is held while gup_fast_fallback() may acquire
mmap_lock.

Link: https://patch.msgid.link/r/CD68F549BF3761B7+20260709050800.520607-1-peiyang_he@smail.nju.edu.cn
Reported-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Closes: https://lore.kernel.org/all/E8540D7D05768C91+8b2ef227-3368-494e-909d-7b28e1489dfb@smail.nju.edu.cn/
Fixes: 71db84a092c3 ("iommufd: Add DMABUF to iopt_pages")
Cc: stable@vger.kernel.org
Tested-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
drivers/iommu/iommufd/pages.c

index 03c8379bbc347e4790d280b06cf4b7c565cdcf6c..404f31d8f72916c706a19c2d429bf4f14a7f4811 100644 (file)
@@ -2451,6 +2451,9 @@ int iopt_area_add_access(struct iopt_area *area, unsigned long start_index,
        if ((flags & IOMMUFD_ACCESS_RW_WRITE) && !pages->writable)
                return -EPERM;
 
+       if (iopt_is_dmabuf(pages))
+               return -EINVAL;
+
        mutex_lock(&pages->mutex);
        access = iopt_pages_get_exact_access(pages, start_index, last_index);
        if (access) {